← Back to Home

Cozzy Privacy Policy

Version 26 · Effective 2 October 2026

Version: 26

Last Updated: October 2, 2026

Effective: October 2, 2026

Cozzy Finance Limited ('Cozzy', 'we', 'our', or 'us'), a company registered in Ireland (CRO: 812498) with registered office at Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share your personal data when you use the Cozzy mobile application and web dashboard (together, the "Service").

We operate in accordance with the General Data Protection Regulation (GDPR), the ePrivacy Directive, the EU Artificial Intelligence Act, and Irish data protection laws as enforced by the Data Protection Commission (DPC).


1. Not Financial Advice

Cozzy is an educational and informational tool. We are not providing financial, investment, tax, legal, or other professional advice. Any insights, categorisations, projections, or content shown in the Service are for general information only and should not be relied upon as a substitute for advice from a qualified professional.


2. Age Requirements

Cozzy is intended for users aged 16 and over.

If you are under 16 you are not permitted to use the Service. By creating an account you confirm that you are at least 16 years old. If you are aged 16 or 17, we encourage you to review this Privacy Policy with a parent or guardian.

We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at privacy@cozzy.io so we can delete it. The age of digital consent in Ireland is 16 (Data Protection Act 2018, Section 31). In the United Kingdom it is 13 (UK GDPR, Article 8(1)). We apply the higher threshold of 16.


3. Who We Are (Data Controller)

  • Name: Cozzy Finance Limited
  • CRO Number: 812498
  • Registered Address: Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland
  • Email: support@cozzy.io

We have assessed our obligations under GDPR Article 37 and determined that a Data Protection Officer is not formally required at our current scale of operations. We review this assessment annually and maintain a documented record. Data Protection Contact: privacy@cozzy.io, for all data protection queries, data subject access requests, or complaints. Requests sent to support@cozzy.io will be forwarded to the Data Protection Contact without delay.

As Cozzy Finance Limited is established in Ireland (an EU Member State), no EU representative under GDPR Article 27 is required. For users in the United Kingdom, our UK contact point for data protection matters is privacy@cozzy.io.


4. Data We Collect

A. Information You Provide

  • Account Information: When you sign in via email, Google, or Apple, we collect your name and email address. If you sign in via Google or Apple, we may also collect your profile picture.
  • Customer Support: Any information you provide when you contact us for help.
  • Statement Files You Upload: If you use Import from file, we read the bank statement or CSV file you choose so that its transactions can be added to an account you select. We extract dates, amounts, descriptions and, where present, running balances. We process the file in memory and do not store the file itself, except where you choose to send it to us (see §10.9). Extracted rows are held for up to 24 hours while you review them; rows you do not import are deleted when you finish or when that period ends. Transactions you import are financial data as described in §4B and are treated in the same way as transactions you enter by hand.
  • Statement Files You Choose to Send to Us: If Import from file cannot read the layout of a file you upload, you can choose to send that file to Cozzy support so that we can fix the import. Nothing is sent unless you tick the consent box on the refusal screen, which is unticked by default and applies to that one file only. The file is sent exactly as you uploaded it, so it contains the dates, amounts, descriptions and, where present, running balances of its transactions, and any account identifiers (for example an IBAN or account number) that the file holds. This is the only case in which we keep a copy of an uploaded file. See §10.9.

B. Financial Data (via Open Banking)

To provide account aggregation and financial insights, we use Yapily Connect UAB ('Yapily'), an authorised Account Information Service Provider regulated by the Bank of Lithuania (payment institution licence No. 53), which provides this service to users in Ireland and the rest of the EEA. When you connect a bank account, you explicitly consent to Yapily accessing your data.

  • Data Processed: Account numbers, balances, transaction history, account holder names, and counterparty information on incoming/outgoing transactions.
  • Storage: We store this data on our backend (Supabase, see §6).
  • Note: We do not see or store your bank login credentials.

Indirect collection (Article 14). Some personal data, in particular the names of counterparties to your transactions (payees, employers, merchants), is collected indirectly from your bank via Yapily, rather than directly from you. We obtain this data under GDPR Article 14 on the legal bases set out in §5, and process it to display and categorise your account activity. Where our automated categorisation assigns a category to a merchant description, that category mapping may also be reused for other users once the same sanitised merchant description has independently been categorised for at least three different accounts (a "k-anonymity" threshold). This reduces, but does not eliminate, the residual risk that a rare, name-shaped description slips past the automated filters we apply before a mapping is shared. Whether your account contributed to a shared mapping is tracked only by a one-way cryptographic pseudonym derived from your account, never your raw account identity; if you delete your account, that pseudonym is deleted, and any shared mapping that depends on it to stay at or above the three-account threshold is removed too (see §8). Where any such third party makes a request to exercise their rights against us, we will respond in accordance with §9.

Art. 14(5)(b): Disproportionate effort exemption. We do not separately notify counterparties whose names appear in your transactions. Taking into account the absence of any direct relationship between Cozzy and those persons, our lack of contact details for them, and the strict, ledger-display-only use of their data, individual notice would involve disproportionate effort within the meaning of GDPR Article 14(5)(b). This Privacy Policy serves as the public notice contemplated by that provision. Counterparties may exercise their data-subject rights at privacy@cozzy.io.

C. Device & Usage Data

  • Identifiers: Device ID, IP address. The Firebase Installation ID and Firebase Cloud Messaging (FCM) device token are created only after you opt in to a Firebase-backed feature; see §6 and the Cookie Policy.
  • Usage Data: How you use the Service, and crash logs and error diagnostics (a strictly-necessary security and stability measure; see §5 and §6, Sentry).
  • Performance data (with your consent): Where you consent to analytics, we use Firebase Performance Monitoring (see §6). Its automatic instrumentation collects app-start time, foreground/background state, and screen-rendering performance, and, through a network interceptor, traces of the HTTP/S requests the App makes, including the request URL, HTTP response code, payload size, and timing of calls to our API. We also record a small number of custom timing traces (e.g. how long a Cozzy AI Assistant response takes). This data is transmitted to Google and is not collected unless you opt in to analytics.
  • Device-integrity data (Talsec freeRASP): The App runs security checks on your device, for example for jailbreak, root, hooking frameworks, debuggers and emulators. As part of its normal operation, the Talsec freeRASP component in the App sends the results of these checks to our security partner Talsec together with: an app instance identifier and a device identifier; your IP address; and your device model and operating system. From your IP address, Talsec works out your approximate location (country, region and city) and your network operator on its own server; the App does not send these to Talsec directly (see §6 and §7).

D. User-Generated Content (Education Hub)

If you submit comments or contributions in the in-App Education Hub, the text of your submission is processed for moderation (see §6, Google Perspective API). An inline notice at the comment box informs you that automated screening is in use, in accordance with EU AI Act Article 50(2).


5. Legal Basis for Processing

  • Consent: Connecting bank accounts (Open Banking), Firebase Analytics, Firebase Performance Monitoring, Sentry performance tracing, the optional Cozzy AI Assistant, AI Auto Categorisation for Expert-tier users, statement layout detection when you upload a file in a layout we have not seen before (see §10.8), and sending a refused statement file to Cozzy support (see §10.9).
  • Contract: Providing the Service's core features (excluding the AI features described above) and managing your subscription.
  • Strictly Necessary Exemption (ePrivacy): Essential client-side storage required for the Service to function, and the minimal device storage used by the crash/error-diagnostics SDK (Sentry) to detect and report faults that threaten the security or stability of the Service: Reg. 5(5) S.I. No. 336/2011 (Ireland); Reg. 6(4) PECR 2003 (UK).
  • Legal Obligation: Compliance with financial or tax regulations applicable to us.
  • Legitimate Interest (Art. 6(1)(f)): Crash and error diagnostics (Sentry EU) necessary to maintain the security, stability, and integrity of the Service; account recovery / wind-down processing in the 30 days following account closure; security and abuse-prevention audit logs; transmission of device-integrity signals via Talsec freeRASP; comment moderation; transactional email delivery; hosting; and indirect-collection counterparty data processing. A balancing test is documented in each case. You may object under Article 21 (see §9).

6. Third-Party Services (Data Processors and Sub-Processors)

Service ProviderRolePurposeData Shared
Yapily Connect UAB (Lithuania), the authorised AISP for users in Ireland and the EEA, with the API platform provided by Yapily Limited (UK)Independent controller during bank authentication; our processor (Art. 28) during account-data retrievalOpen Banking connectivityOAuth tokens, financial account & transaction data. See Yapily Privacy Policy.
Supabase (EU)Processor (Art. 28)Authentication, database, storageUser ID, email, hashed credentials, OAuth tokens, session data, encrypted app data. Hosted in eu-west-1 (Ireland).
Railway (EU)Processor (Art. 28)Application hostingAll API request/response data in transit (TLS), pseudonymised request logs. Hosted in eu-west (Amsterdam, Netherlands).
Google Firebase: AnalyticsProcessor (Art. 28)Product analyticsPseudonymised usage events, device-level identifiers. Requires your consent. Firebase SDK is not initialised until you opt in. Operated by Google on its global infrastructure; transfers outside the EEA are covered by the Standard Contractual Clauses (and the EU-US Data Privacy Framework where Google remains certified); see §7.
Google Firebase: Performance MonitoringProcessor (Art. 28)App performance and network-latency diagnosticsAutomatic traces (app start, foreground/background, screen rendering) and HTTP/S network-request traces (request URLs, response codes, payload sizes and timings) for calls to our API, plus custom timing traces, device model/OS, app version, and approximate location derived from IP. Operated by Google on its global infrastructure (see §7). Requires your consent (shares the analytics consent gate); not initialised until you opt in.
Sentry (Functional Software, Inc.; EU cloud)Processor (Art. 28)Crash and error diagnosticsStack traces, device model, OS version, app version. User IDs are pseudonymised (one-way hash) before transmission and attached only after you sign in; `sendDefaultPii` is disabled (no IP address). Hosted at `de.sentry.io` (Frankfurt, Germany). Strictly necessary for the security and stability of the Service: the Sentry SDK initialises at startup, independently of the analytics consent gate, and is not used for advertising or profiling. Performance tracing is separate and consent-based. You may object to this processing under Article 21 (see §9).
Google Firebase: Cloud Messaging (FCM)Processor (Art. 28)Push notification deliveryFCM device token, notification payload. Active only when push notifications are enabled. Operated by Google on its global infrastructure; transfers outside the EEA are covered by the Standard Contractual Clauses (and the EU-US Data Privacy Framework where Google remains certified); see §7.
Google Cloud Vertex AI (Gemini)Processor (Art. 28)Optional AI assistant, AI transaction categorisation, and statement layout detection (consent-based, see §10)Sanitised transaction descriptions and aggregated financial summaries (assistant); sanitised merchant names and generalised transaction descriptions, together with the transaction's direction, and, where the bank's description does not identify the merchant, the payee or payer name recorded on the transaction with the transaction's amount and currency (categorisation); the header row and up to ten sample rows of an uploaded statement file with transaction descriptions redacted; an IBAN-shaped account-number/IBAN column, if present (including in the header row), masked to its country code, check digits and last 4 characters; other structural columns sent as-is (layout detection, see §10.8). Processed in Google Cloud's EU multi-region (`eu`), within data centres located in the European Union. Not used by Google to train its models.
Google Perspective API (US)Processor (Art. 28)Automated moderation of user comments in the Education HubSubmitted comment text. Transferred to the United States under Standard Contractual Clauses; we additionally rely on the EU-US Data Privacy Framework where the recipient remains certified at the time of transfer. Moderation fails open.
Talsec freeRASP (Talsec a.s. / contracting entity Lynx SFT s.r.o., Czech Republic; telemetry hosted in the US)Processor for the security checks; independent controller for its own uses (see §7)Mobile runtime application self-protection (root, jailbreak, debugger, hooking framework, and emulator detection)Security-check results and threat events, sent with an app instance identifier, a device identifier, IP address, device model and OS (see §4C); Talsec derives approximate location (country, region, city) and network operator from that IP address. Stored in a Talsec database hosted on AWS in the United States (see §7). No account data or financial data. High-severity events are forwarded by Talsec by email to our security team. Talsec also uses this data for its own product improvement, aggregated analytics and security reports (see §7).
RevenueCat (US)Processor (Art. 28)Subscription managementPurchase receipts, user UUID, subscription tier. Transferred to the United States under Standard Contractual Clauses.
Resend (US)Processor (Art. 28)Transactional email deliveryRecipient email address, name, and the contents of system-generated notifications. Transferred to the United States under Standard Contractual Clauses; we additionally rely on the EU-US Data Privacy Framework where the recipient remains certified at the time of transfer.

No advertising. Cozzy does not display third-party advertising in any surface and does not integrate any advertising SDK (e.g. Google AdMob). Cozzy does not collect or use the iOS IDFA or the Android Advertising ID, and does not share data with advertising networks. We will notify you and obtain a fresh legal basis before introducing any advertising-related processing.


7. International Data Transfers

The Service is primarily hosted in the European Union: Supabase in eu-west-1 (Ireland), Railway in eu-west (Amsterdam, Netherlands), Vertex AI in Google Cloud's EU multi-region (`eu`), within data centres located in the European Union, and Sentry at de.sentry.io (Frankfurt, Germany).

Sub-processors that may process data outside the EU/EEA: RevenueCat, Resend, and Google Perspective API (all in the United States); and the Google Firebase services we use, Analytics, Performance Monitoring, and Cloud Messaging (FCM), which Google operates on its global infrastructure and which are not EU-region-pinned. The primary transfer mechanism is the Standard Contractual Clauses. Where the recipient remains certified under the EU-US Data Privacy Framework at the time of transfer, we may additionally rely on the DPF. A copy of the safeguards relied on for any transfer, including the current certification status of each US recipient, is available on request from privacy@cozzy.io.

Remote access to EU-hosted data. Although Supabase and Railway host our data in the European Union, their support and operations personnel may access it from the United States under their data-processing agreements. Separately, Sentry stores account and administrative data (not error telemetry, which remains in Frankfurt) in the United States. Each of these flows is covered by the 2021 Standard Contractual Clauses.

Separately, the freeRASP component of our device-integrity partner Talsec (contracting entity Lynx SFT s.r.o., Czech Republic) sends the data described in §4C to a database Talsec runs on Amazon Web Services in the United States. Talsec works out your approximate location and network operator from your IP address. This is personal data. Versions 17 to 21 of this policy described it as anonymous technical data; that was not correct. It contains no account data or financial data. As well as running the security checks for us, Talsec uses this data for its own purposes: improving its products, aggregated analytics, and security reports and articles. Talsec does not offer a data processing agreement or Standard Contractual Clauses for freeRASP, and we have no contract with Talsec that contains any transfer safeguard, so the safeguards described above do not apply to this transfer. We are replacing freeRASP with device-integrity checks that send no data to Talsec or to anyone outside the EEA, and we will update this policy when we do.


8. Data Retention & Deletion

Data CategoryRetention PeriodLegal Basis / Justification
Account informationDuration of accountContract performance (Art. 6(1)(b))
Account information after closure30 days from account closureLegitimate interest in account recovery, wind-down processing, and dispute resolution (Art. 6(1)(f))
Financial / transaction data (including AI-assigned categories)Duration of accountContract performance (Art. 6(1)(b))
Uploaded statement filesNot stored, except a file you choose to send to Cozzy support (see §10.9 and the row below). Extracted rows pending review: up to 24 hoursContract (Art. 6(1)(b)): providing the import you requested
Statement file you chose to send to Cozzy support30 days, or until you delete itConsent (Art. 6(1)(a))
Statement layout mapping (no personal data; see §10.8)Retained indefinitelyLegitimate interest (Art. 6(1)(f)): avoiding repeat AI calls for uploads in a previously-seen layout
Shared category mapping (cross-user, k-anonymised; see §4B)Up to 180 days, or sooner if fewer than 3 contributing accounts remainLegitimate interest (Art. 6(1)(f)): efficient categorisation without a repeat AI call for a merchant already resolved by other users, limited to mappings at least 3 accounts have independently produced
Your pseudonymised contribution marker for a shared category mapping (see §4B)Until your account is deletedLegitimate interest (Art. 6(1)(f)): needed to count distinct contributing accounts toward the 3-account threshold and to identify your OWN contribution for removal on deletion
AI insights (Cozzy AI Assistant responses)Duration of account or until AI consent withdrawnConsent (Art. 6(1)(a))
AI Auto Categorisation audit logs90 daysLegitimate interest in service quality and debugging
AI interaction audit logs90 daysLegitimate interest in security auditing and abuse prevention
AI security event logs365 daysLegitimate interest in fraud prevention and incident investigation
Vertex AI abuse monitoring data (Google)Up to 55 daysManaged by Google under the Cloud Data Processing Addendum. Data is PII-scrubbed before transmission.
Comment moderation (Perspective API requests)Not retained by Cozzy beyond the moderation decision; Google retention governed by Google's policiesLegitimate interest in safety of user-generated content
Talsec threat eventsRetained in Talsec's US-hosted (AWS) database per Talsec's policy; high-severity events also surfaced in our security inbox and retained per §Support correspondenceLegitimate interest in fraud prevention and platform integrity
Analytics data14 monthsFirebase Analytics default; data minimisation (Art. 5(1)(e))
Performance monitoring traces90 daysFirebase Performance Monitoring default; data minimisation (Art. 5(1)(e))
Crash logs and error events90 daysLegitimate interest in service security and stability (Art. 6(1)(f)); data minimisation (Art. 5(1)(e))
Cookie / consent records6 months (then renewal prompt)DPC guidance on consent renewal cycles
Support correspondence2 years from resolutionCustomer service and dispute resolution
  • Deletion: You can delete your account and all associated data immediately via Settings > Delete Account.
  • Effect of Deletion: We delete your data from Supabase, revoke bank access tokens, anonymise audit logs, and delete all AI-generated insights and history.
  • AI Consent Withdrawal: When you disable the Cozzy AI Assistant, we immediately delete your stored AI insight history and cached responses. When you switch the AI Auto Categorisation toggle off, no further AI categorisation is performed; previously assigned categories remain attached to your transactions (you can overwrite or clear them manually).

Data Breach Notification. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay in accordance with GDPR Article 34, and the DPC within 72 hours where required under Article 33.


9. Your Rights

Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, to withdraw consent at any time, and to lodge a complaint with a supervisory authority (Art. 77); see §14. Where we rely on legitimate interest (including crash and error diagnostics), you have the right to object under Article 21.

To exercise these rights, please contact us at privacy@cozzy.io. We will normally verify your identity by replying to the registered email on your account. We will respond without undue delay and within one month of receipt. For complex or high-volume requests we may extend by a further two months, in which case we will tell you within the first month. Requests are handled free of charge except where they are manifestly unfounded or excessive (Art. 12(5)).


10. Automated Decision-Making, Profiling, and AI

10.1 Overview

Cozzy uses artificial intelligence in two distinct, opt-in flows:

1. Cozzy AI Assistant: optional, consent-based, default OFF. Available across paid tiers. This toggle (`generativeAiEnabled`) also gates statement layout detection (see §10.8): when it is on and you upload a file in a layout we have not seen before, a further AI call identifies the file's columns.

2. AI Auto Categorisation: Expert-tier subscription feature, default OFF. Controlled by the "Auto Categorisation" toggle under Settings > Preferences. On first upgrade to Expert you are shown a one-time prompt asking whether to enable the feature; the legal basis is your explicit consent (Art. 6(1)(a)). Switching the toggle off stops further AI categorisation immediately.

Free and Beginner-tier users do not have access to AI Auto Categorisation; no transaction data is sent to Vertex AI for categorisation purposes for users on those tiers.

All three uses (assistant, categorisation, and statement layout detection) run on Google Gemini via Google Cloud Vertex AI in Google Cloud's EU multi-region (`eu`), within data centres located in the European Union.

10.2 No Automated Decisions with Legal Effect

These AI features are advisory and informational only. They do not produce legal effects or similarly significant effects on you within the meaning of GDPR Article 22(1). You may override any AI-generated categorisation at any time, and you retain the right to obtain human intervention, express your point of view, and contest any AI output by contacting privacy@cozzy.io.

10.3 What Data Is Processed by AI

Before any data is sent to the AI model, we apply automated heuristic filters designed to remove personal identifiers (account numbers, IBANs, sort codes, email addresses, phone numbers, personal names, card numbers, transaction reference numbers) from transaction descriptions. These filters are the operative safeguard under our DPIA: their effectiveness is reviewed periodically and they constitute the legal basis on which we conclude that the data sent to the model is not, in practice, personal data save for residual leakage. The same filters, together with the k-anonymity threshold described at §4B, gate whether an automated categorisation is ever shared with other users at all.

Special-category data (Art. 9). We apply additional filters intended to suppress transaction descriptions that may reveal health information (e.g. medical providers), religious affiliation, political opinions, or trade union membership. We acknowledge no automated filter is perfect. Where Article 9 data is nonetheless processed, we rely on your explicit consent under Article 9(2)(a), given at the granular AI feature opt-in. When you opt in to the Cozzy AI Assistant or to AI Auto Categorisation, you are asked to confirm that you understand the small residual risk of special-category data being inferred from your transaction descriptions, and that you consent to that processing.

For the AI Assistant: only sanitised merchant names, generalised transaction descriptions (capped at 80 characters), and aggregated financial summaries are sent; no raw bank data is sent. For AI Auto Categorisation: for each transaction, only its sanitised merchant name or generalised description (capped at 80 characters) and whether it is money in or money out are sent; where your bank's description does not identify the merchant (for example a bare transfer reference), the payee or payer name recorded on the transaction is used in its place and the transaction's amount and currency are sent with it; no account names, dates, times, balances or raw bank data are sent. Statement layout detection is the one exception to this: it sends a partially redacted sample of rows from a file you are actively uploading, on the narrower basis set out at §10.8.

10.4 Your Control Over AI Features

  • Cozzy AI Assistant (default OFF): Toggle under Settings > Preferences > AI Features > AI Insights. Disabling the Cozzy AI Assistant immediately deletes your stored insight history and cached responses, and stops statement layout detection (§10.8).
  • AI Auto Categorisation (Expert tier only, default OFF): Toggle under Settings > Preferences > Auto Categorisation. Available only when your subscription tier is Expert. Switching the toggle off stops further AI categorisation immediately.

10.5 EU AI Act Transparency (Article 50)

  • Cozzy AI Assistant output is labelled "AI-powered by Gemini" at the point of display.
  • Transactions categorised by AI display an "AI" indicator distinguishing them from manually categorised or rule-based results.
  • The Education Hub comment box carries an inline notice ("Comments are screened by an automated classifier.") so that you are informed at the point of interaction that an AI moderation system is in use (Art. 50(2)).
  • Outputs may occasionally contain inaccuracies. Verify important financial information against your official bank statements.
  • You have the right to request human review of any automated output by contacting privacy@cozzy.io.

10.6 Profiling

Cozzy analyses your financial data to identify spending patterns, trends, and categories. This constitutes profiling within the meaning of GDPR Article 4(4).

Article 22 status. Profiling outputs are displayed to you as informational insights only. They do not constitute a decision based solely on automated processing within the meaning of Article 22(1): they do not restrict your access to any feature, affect your subscription tier, influence credit decisions, or produce any legal or similarly significant effects. Any action, such as adjusting a budget or moving money, is taken by you, not by the Service. Profiling outputs are not shared with third parties for marketing, advertising, or credit-scoring purposes. You can disable AI-powered profiling at any time via Settings > Preferences > AI Features.

10.7 Data Protection Impact Assessment

We have conducted a Data Protection Impact Assessment (DPIA) covering our AI processing and Open Banking data aggregation operations, in accordance with GDPR Article 35. A summary is available on request from privacy@cozzy.io.

10.8 Statement Layout Detection

If you have the Cozzy AI Assistant toggle (§10.4) switched on and you upload a statement file in a layout we have not seen before, we send the file's header row and up to ten sample rows to Google Cloud Vertex AI so that it can identify which columns hold the date, amount and description. Transaction descriptions in those rows are redacted before they are sent. Any IBAN-shaped value in those rows, or in the header row itself, is masked to its country code, check digits and last 4 characters before it is sent, for example IE29AIBK93115212345678 becomes IE29…5678. Other structural columns in those sample rows that are not IBAN-shaped, such as a bare account number, sort code, date or amount, are sent to Vertex AI exactly as they appear in the file, unredacted. The result describes the layout of the file only and contains no personal data; we keep it indefinitely (see §8) so that later uploads in the same layout do not need this step. If the Cozzy AI Assistant toggle is off, Cozzy reads only simple statement layouts on its own servers and nothing is sent to Vertex AI; other layouts cannot be imported until the assistant is turned on.

10.9 Sending a Refused File to Cozzy

If Import from file cannot read the layout of a statement file you upload, the refusal screen offers a button, "Send this file to Cozzy". This is optional. The consent box is unticked by default and applies to that one file only; nothing is sent unless you tick it. If you do, the app sends us the exact file you uploaded, and we use it only to fix the import so that the layout can be read.

The file is not redacted, so it contains whatever the file contains: transaction dates, amounts, descriptions, balances, and any account identifiers (for example an IBAN or account number). We store it encrypted at rest in a private bucket in our Supabase storage in the EU, for a maximum of 30 days, after which it is deleted automatically. Access to the file through our admin tools is restricted to permissioned Cozzy staff and each such access is logged. Our storage provider, Supabase, holds the file for us (see §6). The file is never sent to Google Cloud Vertex AI, to Sentry, or to any other third party (Supabase, our processor, only stores it for us; see §6), and it is never used to train any model or for any purpose other than fixing the import. The legal basis is your consent (Art. 6(1)(a)). We record the version of this policy you consented to and the time you consented.

You can delete the file sooner at any time under Settings > Data & Privacy > "Files shared with Cozzy". Deleting it withdraws your consent and removes the file immediately; withdrawal does not affect the lawfulness of our storing it before then. Deleting your account also deletes it. If you do not send the file, the file itself is not kept: as described in §4A, we process it in memory and only the extracted rows pending your review are held, for up to 24 hours.


11. Cookie Policy

See our standalone Cookie Policy. In summary, the Service uses (a) essential client-side storage; (b) analytics (Firebase Analytics) and performance monitoring (Firebase Performance Monitoring), both of which require your explicit consent and are not initialised on your device until you accept (performance monitoring additionally shares the request URLs of calls to our API with Google); crash and error diagnostics (Sentry EU), which are strictly necessary for the security and stability of the Service and initialise at startup with `sendDefaultPii` disabled and no advertising use; and (c) push-notification tokens (FCM) where you have enabled notifications. Our web surfaces use only essential / functional cookies (persistent theme-preference cookies on the web dashboard and blog, retained for up to 365 days; post-form-submission waitlist confirmation with 365-day retention) and therefore do not display a consent banner.


12. Security Measures

We implement appropriate technical and organisational measures to protect your personal data, including encryption at rest and in transit (TLS 1.2+), row-level security on all database tables, automated PII scrubbing before external AI processing, rate limiting on all API endpoints, mobile app integrity verification via Talsec freeRASP (detection runs locally on your device; the check results, device identifiers and IP address are transmitted to Talsec's US-hosted (AWS) backend, which derives your approximate location from that IP address; see §4C and §7), and access controls based on the principle of least privilege. Bank consent tokens are encrypted with AES-256-GCM at rest. A fuller, plain-English description of these measures is published in our Security Policy. That page is informational and does not form part of this Privacy Policy.


13. Version History

  • v26 (October 2026): New Section 10.9 discloses that, if Import from file cannot read the layout of a statement file you upload, you can choose to send that file to Cozzy support so that we can fix the import. It is sent only if you tick a consent box that is unticked by default, for that one file; it is stored encrypted for up to 30 days in our EU Supabase storage, has its access through our admin tools restricted to permissioned Cozzy staff with each such access logged, is never sent to Google Cloud Vertex AI or to any other third party, and you can delete it sooner at any time under Settings > Data & Privacy > "Files shared with Cozzy". The legal basis is consent (Art. 6(1)(a)). Section 4A (the data), Section 5 (the legal basis) and Section 8 (the retention table) are updated to match. No change to any other processing.
  • v25 (October 2026): Section 6 (the Google Cloud Vertex AI row) and Section 10.3 now disclose that AI Auto Categorisation sends the payee or payer name recorded on the transaction with the transaction's amount and currency when the description does not identify the merchant, alongside the sanitised merchant name or generalised description and the transaction's direction (money in or money out) (ENG-2125), because the description alone could not tell a mortgage payment to a bank from a grocery shop. Section 10.3 is split so that it states separately what is sent for the Cozzy AI Assistant and for AI Auto Categorisation. No change to the legal basis (Consent, Section 5), to the processor, to the processing location, to retention, or to any other processing. Free and Beginner-tier users remain excluded: nothing is sent for them.
  • v24 (September 2026): Section 4B (Indirect collection) now discloses that an automated merchant categorisation may be reused across users once the same sanitised merchant description has independently been categorised for at least 3 different accounts (a k-anonymity threshold, ENG-2029, counting distinct contributors per description rather than agreement on a category), that this reduces but does not eliminate the residual name-leakage risk, that contribution is tracked only by a one-way pseudonym of the account, and that both the pseudonym and any shared mapping depending on it are removed on account deletion. Section 10.3 gains one sentence naming this threshold and pointing to Section 4B for the full disclosure. Section 8 gains two retention rows: the shared category mapping itself (up to 180 days, or sooner on the k-anonymity threshold dropping below 3 contributors) and your own pseudonymised contribution marker (until account deletion). No change to the legal basis (Section 5 is unchanged: categorisation stays on consent), to what is sent to the AI processor, or to the processor itself.
  • v23 (September 2026): Vertex AI processing location corrected. Section 6, Section 7 and Section 10.1 are corrected: this corrects the Vertex AI processing location from the single region europe-west3 (Frankfurt, Germany) to Google Cloud's EU multi-region (data centres within the European Union), matching where processing moved on 25 September 2026 (ENG-1935). No change to the legal basis (Consent, Section 5), to what is sent, or to the processor (Google Cloud EMEA Ltd); EU-to-EU, no international transfer arises.
  • v22 (September 2026): Talsec freeRASP disclosure corrected. Section 4C now lists the data the freeRASP component sends to Talsec: the security-check results together with an app instance identifier and a device identifier, IP address, device model and operating system; it also discloses that Talsec works out your approximate location (country, region, city) and network operator itself, from that IP address, rather than the App sending them. Section 6, Section 7 and Section 12 are updated to match. Section 7 now states that this data is personal data hosted in the United States, that Talsec does not offer a data processing agreement or Standard Contractual Clauses for it, and that Talsec also uses this data for its own purposes (product improvement, aggregated analytics, and security reports and articles) as an independent controller; versions 17 to 21 described it as anonymous technical data, which was not correct. No change to any other processing.
  • v21 (September 2026): Section 10.8 (Statement Layout Detection)'s last sentence corrected: when the Cozzy AI Assistant toggle is off, Cozzy now reads only simple statement layouts on its own servers, with nothing sent to Google Cloud Vertex AI, and a layout it cannot read this way cannot be imported until the assistant is turned on. This replaces the earlier sentence, unchanged since v19, stating that a consent-off user assigns the columns themselves and nothing happens; that no longer matched the shipped consent-off import experience (ENG-1686), which resolves an unambiguous layout with a deterministic, in-house heuristic and refuses an ambiguous one rather than offering a manual mapping screen that was never built. No change to the legal basis (Consent, Section 5) for the on-path Vertex AI call, to Section 10.3's scoping language, or to any other processing.
  • v20 (September 2026): Section 10.8 (Statement Layout Detection) corrected: an IBAN-shaped value in the sample rows sent to Google Cloud Vertex AI, or in the header row itself, is now masked to its country code, check digits and last 4 characters before it is sent (for example, IE29AIBK93115212345678 becomes IE29…5678), rather than sent as-is as v19 stated; a structural column that is not IBAN-shaped (a bare account number, sort code, date, or amount) is still sent exactly as it appears. Section 6's Vertex AI row is updated to match. This corrects an over-disclosure: the code (ENG-1757, `CellShapeClassifier.maskIban`) sends less identifying data than v19 stated. v20 also corrects the Vertex AI processing region named in Section 6, Section 7, and Section 10.1 from europe-west1 (Belgium) to europe-west3 (Frankfurt, Germany), matching where Vertex AI processing actually moved to on 9 September 2026 (ENG-1495). No change to the legal basis (Consent, Section 5) or to any other processing.
  • v19 (September 2026): Section 10.8 (Statement Layout Detection) now discloses that, alongside the redacted transaction descriptions, other columns in the sample rows sent to Google Cloud Vertex AI, including an account number or IBAN column if the file has one, are sent exactly as they appear in the file and are not redacted. Section 6's Vertex AI row and Section 10.3's data-processed description are updated to match. This makes explicit what our sub-processor register already recorded about that data flow. No change to the legal basis (Consent, Section 5), to Section 10.3's scoping of the identifier-filter safeguard away from layout detection, or to any other processing.
  • v18 (September 2026): The AI assistant is renamed from "Olivia" to "the Cozzy AI Assistant" throughout this policy (Cozzy is now the persona and the product; no change to the underlying processing). Section 8's retention row for financial and transaction data corrected from "Duration of account + 6 years" to "Duration of account" on a contract basis, matching how account deletion actually works: no 6-year post-closure retention of financial data has ever been implemented. New disclosures for Import from file: Section 4A discloses the data extracted from uploaded statement files (not stored; extracted rows pending review held up to 24 hours); Section 5, Section 6 (sub-processor table), Section 8 (retention table), and new Section 10.8 disclose statement layout detection via Google Cloud Vertex AI, gated by the same Cozzy AI Assistant toggle as the assistant itself: when that toggle is on and you upload a file in a layout we have not seen before, its header row and up to ten sample rows (descriptions redacted) are sent to identify the date, amount and description columns; the result contains no personal data and is kept indefinitely as a technical mapping.
  • v17 (July 2026): Talsec/freeRASP disclosure corrected: freeRASP threat-event telemetry is hosted on AWS in the United States, not on an EU backend as previously stated. A dedicated §7 paragraph now discloses the US hosting and the basis for it: the telemetry is limited to technical threat-event data with no direct identifiers, account data, or financial data, and is treated as anonymous technical data rather than personal data (Talsec a.s. is an EEA company and is not certified under the EU-US Data Privacy Framework). §6 (sub-processor table), §8 (retention row), and §12 (security measures) corrected to match. The data concerned is unchanged: anonymous technical threat-event metadata with no direct identifiers or financial data. §11 cookie summary corrected: the web dashboard and blog theme-preference cookies are persistent (up to 365 days), not session-only; see Cookie Policy v12 for the full inventory. Also records that on 5 July 2026 the v16 text received an in-place factual erratum correcting the Vertex AI region from europe-west4 (Netherlands) to europe-west1 (Belgium): both EU regions, no change to processing or safeguards.
  • v16 (June 2026): Firebase Performance Monitoring disclosed as a consent-gated sub-processor (shares the Firebase Analytics consent gate). Its automatic instrumentation captures app-start/screen-render traces and HTTP/S network-request traces (including request URLs, response codes, payload sizes and timings) which are transmitted to Google; disclosed in §4C (Device & Usage Data), §5 (consent list), §6 (sub-processor table), §7 (international transfers: Google global infrastructure, SCC/DPF), and §8 (retention, 90 days). §6 and §7 also now state explicitly that the existing Firebase Analytics and Cloud Messaging (FCM) services are operated by Google on global infrastructure and that any non-EEA transfer relies on the SCCs (and DPF where certified). Sentry posture unchanged.
  • v15 (June 2026): Crash and error diagnostics (Sentry EU) reclassified as strictly necessary for service security and stability (ePrivacy Art. 5(3) exemption) and processed under legitimate interest (Art. 6(1)(f)), no longer consent-gated. The Sentry SDK now initialises at startup to capture cold-start and onboarding crashes; `sendDefaultPii` disabled, no IP address, user ID pseudonymised and attached only after sign-in. Article 21 objection right added to §9. Sentry performance tracing remains consent-based. Firebase Analytics consent unchanged.
  • v14 (June 2026): Replaced Firebase Crashlytics with Sentry EU (Functional Software, Inc., `de.sentry.io`, Frankfurt, Germany) for crash and error reporting. User IDs pseudonymised before transmission; `sendDefaultPii` disabled. Crashlytics removed from consent list, sub-processor table, cookie summary, and retention schedule.
  • v13 (May 2026): Art. 14(5)(b) disproportionate-effort exemption added to §4 indirect-collection notice, naming the safeguards relied on; cookie-policy summary in §11 updated to reflect 365-day waitlist retention and removal of the email cookie.
  • v12 (May 2026): Talsec/freeRASP corrected to processor (threat events are transmitted to Talsec's EU backend, not on-device-only); Firebase SDK deferral implemented in code, with policy text updated to match; DPF references qualified; Article 9 special-category framing tightened (heuristics as operative safeguard, fresh explicit-consent confirmation at opt-in for residual leakage); account-info retention split into in-account (contract) and 30-day post-closure (legitimate interest).
  • v11 (May 2026): Auto Categorisation reframed as explicit opt-in (default OFF); Art. 14 indirect-collection notice; freeRASP named; profiling clarification; no-advertising disclosure.
  • v10 (May 2026): Sentry removed; Perspective API + FCM added; AI Transaction Categorisation framed as Expert-tier toggle; Supabase + Railway regions pinned.
  • v9 (April 2026): Registered legal entity; Yapily controller/processor split; Crashlytics essential justification; Data Protection Contact; UK contact point.
  • v8 (April 2026): Named Yapily; added Railway, Resend; Vertex AI retention; DPIA; security measures section.
  • v7 (March 2026): AI transparency: Vertex AI disclosed, EU AI Act Article 50 compliance.

14. Contact Us

  • Email: privacy@cozzy.io
  • Support: support@cozzy.io
  • Address: Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland

You also have the right to lodge a complaint with the Irish Data Protection Commission:

  • Website: dataprotection.ie
  • Email: info@dataprotection.ie
  • Postal: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

If you are based in the United Kingdom, you may also contact the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Helpline: 0303 123 1113

© 2026 Cozzy. All rights reserved.